{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/knowns--0.33.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:knowns:knowns:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-86542"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["knowns (\u003c 0.30.0)","knowns (\u003c= 0.33.0)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","cve","vulnerability","path-traversal","mcp"],"_cs_type":"advisory","_cs_vendors":["knowns"],"content_html":"\u003cp\u003eThe knowns application, in versions prior to 0.30.0, contains a critical path traversal vulnerability (CVE-2026-86542) within its import route handling. The application fails to properly validate the 'name' parameter provided during an import operation. By supplying a specially crafted 'name' parameter containing directory traversal sequences (e.g., ../), an unauthenticated attacker can escape the intended 'imports' directory.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation results in the attacker having the ability to overwrite files anywhere on the filesystem that the server process has permissions to access. Because this can lead to remote code execution (e.g., by overwriting configuration files, startup scripts, or web application files), it poses a severe threat to organizations hosting this software. Defenders should prioritize patching knowns to version 0.30.0 or later to remediate the vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-86542 allows an unauthenticated attacker to achieve arbitrary file overwrite on the underlying host. This level of access typically leads to complete compromise of the application instance, potential privilege escalation, and execution of arbitrary code, depending on the files accessible to the application's service account.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the knowns application to version 0.30.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit file system access logs for any evidence of attempts to traverse paths using the '../' sequence within the application's import-related URI paths.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on the application front-end or Web Application Firewall (WAF) to block requests containing directory traversal patterns in URI parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T17:07:43Z","date_published":"2026-09-07T23:37:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86542-knowns-path-traversal/","summary":"An unauthenticated path traversal vulnerability in knowns versions prior to 0.30.0 allows attackers to overwrite arbitrary files on the server by supplying malicious traversal sequences in the import route name parameter.","title":"CVE-2026-86542 Path Traversal in knowns Application","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86542-knowns-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Knowns (\u003c= 0.33.0)","version":"https://jsonfeed.org/version/1.1"}